CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications ea
An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extensio
Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the syste
Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbi
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensit
** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerab
RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to s
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 an
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access l
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, Feb
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths
Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics funct
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via d
A directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720
OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. Th
MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html
The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low
Directory traversal vulnerability in ESS REC Agent Server Edition series allows an authenticated attacker to view or alt
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web
A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation
A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authe
Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unifie
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to
Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox
The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files,
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vu
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vuln
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vu
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vu
A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By craf
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversar
In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path
An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 an
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other appl
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decry
CloudPanel v2.2.2 allows attackers to execute a path traversal.
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privilege
Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with kn
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory trave
Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started